Bug 1187975 - (CVE-2021-22921) VUL-1: CVE-2021-22921: nodejs10,nodejs12,nodejs14,nodejs: Windows installer - Node Installer Local Privilege Escalation
(CVE-2021-22921)
VUL-1: CVE-2021-22921: nodejs10,nodejs12,nodejs14,nodejs: Windows installer -...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Normal
: ---
Assigned To: Adam Majer
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-07-02 13:58 UTC by Robert Frohl
Modified: 2021-07-02 13:58 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2021-07-02 13:58:12 UTC
Windows installer - Node Installer Local Privilege Escalation (Medium) (CVE-2021-22921)

Node.js is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More specifically, improper configuration of permissions in the installation directory allows an attacker to perform two different escalation attacks: PATH and DLL hijacking.

You can read more about it in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22921

Impacts:

    All versions of the 16.x, 14.x, and 12.x releases lines

https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
Comment 1 Robert Frohl 2021-07-02 13:58:34 UTC
not relevant for linux, closing